Securing Cyberpeace – Stel Valavanis, onShore Security
Recently, the Biden Administration announced a new cybersecurity strategy. One of the pillars of the new strategy lays out an intent to work with private entities as contractors to disrupt cybercrime. As the line between cybercrime and cyberwar blurs, the Cybersecurity Tech Accord has released a statement of principles, declaring that they will work to prevent the engagement of cyber mercenaries. Stel Valavanis, as CEO of onShore Security, is a signatory of the principles and the Tech Accord, and believes that steps must be taken now to ensure cyberpeace in the future.
Transcript
This is Techstrong tv. Hey guys, thanks for the thrill. We're here with Stella Vali, who's c e o for onshore security, and we're talking about the change in the tenor of the conversation that as it relates to offensive security.
Stella, welcome to the show. Well, thank you for having me. Not too long ago, we were having this debate for years now that I think about it, but it was always kind of one of these things where the defense department was kinda saying, maybe we should be more aggressive.
And maybe the folks over in the, uh, uh, state Department were saying, well, if you're more aggressive, you're gonna start a war. And that's probably a bad thing. It seems like the tenor of that conversation and tone of it at least, has changed with the National Cybersecurity strategy and other signals from DC where maybe we are gonna get more aggressive.
What's going on? Well, there's been events in the world, uh, uh, you know, uh, it's China, North Korea, Russia. I mean, those are kind of the, you know, the, the big ones each are different.
Uh, China's stolen ip, and, you know, even though there was a little bit of a agreement in place, a verbal agreement to, to back off on that, they, they ramped it right back up. So, uh, that's not necessarily cyber warfare, but it's definitely not the accepted spying, so to speak, tolerated spying. Russia's a little different.
Russia, uh, has been able to have some kind of plausible deniability with the, you know, the criminals that do do the, uh, uh, infrastructure attacks. But I, I, I think we're kind of getting past that and seeing it at cyber warfare. If you look at the Eastern European countries, they've been used to it for a long time.
And, uh, the Baltic countries especially, um, you know, uh, I heard the, uh, uh, uh, higher up in the cyber Estonia go into some detail about the kind of attacks they've been seeing from Russia for years. So, yeah. So the climate's changed, basically.
I know this is the digital age, but is this fundamentally any different than going after the Barbery Pirates? Back in the day when we had ships and we sent, you know, the Navy to go fight these guys and come back and, you know, are we gonna do the same again? Uh, it's identical.
I, I mean, right. I mean, it was basically the, the, the, the, you know, the, one of the British government were happy to see pirates nailing Spanish ships, and then he eventually, uh, you know, they spread their wings, uh, further, you know, and so that was, that also, you know, the case, uh, I think that was us' first foreign involvement was going into the, into the Mediterranean to a, a attack the, the Barbery Pirate. So, um, yeah, I, I, I really think this is history repeating itself To that end.
Um, I get that countries can go and do this, but should individual corporations that have access to resources being engaged in this behavior, or they should, they always defer to the national government. Well, you history tells us that, you know, both have happened and with lots of successes and lots of failures, um, we can't predict the future. Um, but, uh, but that said, it's dangerous, um, the, the federal government and the state governments too.
But, but, and, and not just our federal government, I really think generally have not done the hack back. I mean, it's pretty much been, uh, you know, peace time, uh, so to speak, you know, in, uh, in the cyber realm. And, uh, um, and so, so companies that have chosen to do some of these things very, very quietly, um, they've done so, uh, you know, with, you know, not exactly as their first line.
I mean, this is something they would do, uh, reluctantly. Um, the federal government even saying that they would do something more aggressive, they'd be, you know, add offense to their defense alone, really reduces the, the, the needs. Poor corporations get involved and, and they'd rather not.
Uh, but, um, corporations are very powerful. We, we can name names, and as a result, they are actually, you know, going to be participants. Excellent example is what's going on in Ukraine.
I mean, uh, Microsoft in particular is extremely involved, uh, with, with Ukraine, and don't think that's done without, uh, uh, very close involvement of the United States government. We've also seen the hacker groups of, all right, so I think it's kil net is its name that is now advertising and that it has services for sales. So maybe they're become the digital equivalent of the Wagner Group and the Ukrainian War.
But basically they're saying, we're for hire anywhere in just about any place. So is this all gonna spiral outta control soon? Uh, yes.
And so the, uh, the cyber tech accord, which, um, which we're signatories of, uh, from the get-go now going in, uh, I think we're at five year point now. Yeah, we just did our, our five year, um, meeting at r s a, um, uh, Microsoft's probably the, the, you know, the number one, the main company behind it. And, and, uh, some of the leader positions are with entre, with, uh, excuse me, with Microsoft people.
Um, and, um, uh, our recent announcement was a, um, a, uh, you know, signed, agreed upon initiative and a request to the United Nations who we have the ear of, uh, so all the governments of the world to reject cyber mercenaries, uh, because we see it as a growing threat, uh, because we see cyber mercenaries not as a way to keep our own forces from being involved, but rather to escalate. And so, so we reject it on the grounds of, uh, of trying to keep the peace. Aren't we also involved in something that feels like a cybersecurity AI arms race all of a sudden?
Because, um, we seem to be making a lot of advances, but the bad guys are discovering things like chat G B T as well. So are we entering some sort of new phase without really realizing it? Yeah, uh, it, it's, uh, it, it's early, but it's inevitable.
Um, and I don't know, uh, arms, this would not be a bad, you know, term to use to describe it. Um, but I, I think it's gonna be a lot more complicated than what we can really envision at this point. Uh, you know, a AI is a tool rather than like a replacement for humans.
It empowers humans more than replaces them. I think there's a lot of this thinking about that. It really acts like a human.
Uh, it looks a lot more intelligent than it is. I mean, it, it really, it really doesn't quite have enough context to, to, to do things on its own. That said, it's gonna be very powerful with things like, let's say, iterating, uh, software so that it becomes less detectable.
And an AI can probably do a million tests in a second to find a way to modify, uh, a certain, uh, you know, uh, point in the kill chain to make it less detectable at that point. So, so, so find its flaw. So, so that I, you're probably, that's probably actually the lowest hanging fruit as far as where AI is gonna enter into cyber crime.
You're gonna see malware become more effective, more quickly, vulnerabilities being weaponized more quickly, um, zero days rather being weaponized more quickly. That that's really the first thing you're gonna see. Uh, and then, and then on the defense side, AI's gonna also be better at finding anomalies, uh, identifying activity as suspect, uh, en enrich, uh, um, adding context and enrichments to data that you see on the detection side, because that's a, there's a lot of work to do there.
And AI could do that faster. Think anything that a machine can just do a lot faster, that's the number those are, that's where the low hanging fruit is. The challenge has always been, at least in my mind, is it's never been clear.
If we know for certain where an attack was launched from that bad guys are good at masking that activity and AI may make that even more challenging. So if we're gonna be more offensive, how can we be certain? Yeah, I mean, this, nobody's gotten it down.
Um, you know, to this day there's very, very famous, well-studied investigative attacks with lots of forensics data without a confident attribution. So, so, um, yeah. Uh, I think we're gonna make mistakes.
Um, I think the, you know, the hack back attempts are going to probably, uh, at, at least if his history tells us how it's been with the US government, at least, it's gonna be a little more careful than, than our adversaries have been. They don't mind seem to mind as much if they, um, have some casualties, you know, let's say out of it, we're gonna be a little more careful. Uh, we, we, uh, we would be hurt more by the optics of that, um, uh, for one.
Um, but, uh, you're most likely then gonna see tactics that are, um, that are closer to what we've done in the past, information gathering, triangulating, uh, uh, maybe various kinds of testing, probably waiting for, uh, on the ground type of, uh, validation for high attribution before we do something that is very impactful. Uh, we're gonna be more careful. Is that detrimental to us?
Uh, to some extent, sure. But, uh, but don't, don't, um, don't think that we're, we're going in ill-equipped. I mean, th this is, there, there is no more powerful hacker, uh, in the world than, than, uh, the, the United States federal government entities.
I mean, it's just, we are the best by far. And, and, uh, that doesn't mean that we rest on our laurels. It, it means that, that we have the luxury, let's say, to do it carefully, do it right, and, uh, and minimize casualties.
Are we getting better at collaborating? In theory, my enemy's enemy is my friend, and yet cybersecurity, the history of it has been not really great when it comes to information sharing. So are we getting better at that A little bit?
Um, there's, you know, there's a lot of attempts that focus on the, um, commercial side of things. Um, you know, we're members of a number of information sharing organizations. There's some that are industry focused.
Uh, there are some that happen in certain cyber security communities. Uh, you know, tech Accord is, uh, the cybersecurity tech accord. I was, you know, uh, uh, referencing earlier, uh, you know, as part of that, um, we have certain agreements we put in place about, about sharing data and, uh, and talking about breaches and vulnerabilities.
Uh, there's also been some, uh, uh, uh, legislation coming down that would help with, um, you know, white hat hackers and with, uh, bug bounty, um, uh, you know, uh, what would you wanna call 'em? Freelancers, whatnot, uh, whistleblowers. I mean, those are the kinds of things that enable it full on information sharing.
Um, it's tough, uh, but I think we're, even those things I'm talking about really would move the needle a good bit. Um, I would like full on information sharing the F B I is not a bad container for that. Um, uh, but, uh, but yeah, I don't see anything really full fledged coming out in an near future here.
Are we also getting better at using our, uh, physical resources to track down criminals and in much the same way we went after mobsters with their bank accounts? Or are we doing the same now? Well, you've probably seen some of the news I've seen.
I mean, I, I mean, I, I, I, I'm sure you would agree, you're looking at, let's say, look at a last, you know, two years, uh, you know, way more big Interpol busts, networks being taken down. Um, you know, people being picked up when after a couple years, they didn't know that they, you know, they were not careful about flying to a certain country or another. Yeah, we, we've, we've done a much better job with the, the, the physical side of it and, and connecting those.
And interestingly, uh, um, there have been times where, where Russia and China have been cooperative in those kinds of efforts. Not, not a whole lot, but, uh, um, they have problems with criminals too. Don't think we're alone on that.
We're not the only target far from it. Uh, interp poll's probably been the, you know, the, the most active there. Um, but there is, you know, there's a politics to that of course.
Um, and we're weak on some of the treaties with countries that probably would matter a little more. Um, but, you know, it's, um, uh, I, I do think that I, I'm, I'm kind of optimistic there. I do think that enough of the world, even our adversaries, um, you know, are not a hundred percent adversaries that they see the threats that we see.
And, and even though they might support some things from a nation state perspective, uh, they, to them, the criminals are only useful for a moment. So, so I think you're gonna see more cooperation on the physical front as a result. So, Stella, given all that, what's your best advice to folks as we go forward?
Well, look, we're talking about people with significant assets and, and heavily impacted by any kind of disruption. Uh, you know, and, and don't assume that you're, you are gonna be able to cover everything and who you circumstances that come up dotted lines to, uh, to, uh, D o D and to, uh, to entities that are much more targets. So, honest, I'll, I'll, I'll throw in our, our mantra that we give, you know that the detection is your superpower.
You assume your hack. Assume your perimeter is inadequate. Assume your your devices aren't trusted and, you know, put in detection in this, your protection and additional protection.
Take every protection component you have and integrate that with your detection practice. That's the thing that I, that we not reached the maturity level needed yet, or, All right, folks, you heard it here. I think it's still true.
The best defense is a good offense. And here we are still doing the same thing still. Thanks for being on the show.
You're welcome Back to you guys in the studio.